Fileless LOTL Attacks Dominate with 84% of Incidents

โ–ถ Watch (3:29)

84% of incidents in 2025 involved living-off-the-land binaries, per Bitdefender. Fileless malware operates entirely in RAM and leaves no executable artifacts. LOTL attacks abuse trusted Windows tools like PowerShell, certutil, and bitsadmin. The term originated at Derbycon eight years ago. Attackers exploit human trust through clickfix and malvertisements. Initial access via clickfix reached 47% in 2024, overtaking phishing.

Clickfix Overtakes Phishing as Top Initial Vector

โ–ถ Watch (5:07)

47% of initial access in 2024 came from clickfix attacks, per Microsoft. Victims see fake browser update prompts or Word documents. They follow instructions and install malware. Malvertisements require no user action: JavaScript fingerprints browser plugins to deploy shellcode. This technique targets outdated plugins from 10 years ago. Plugins downloaded from any website often lack patches. Clickfix trumps even phishing, which dominated for a decade.

Four Malware Families Demonstrate the Anatomy

โ–ถ Watch (11:01)

Asteroth uses a .lnk file to launch WMIC, bitsadmin, and certutil. It hides a base64 payload in NTFS alternate data streams and performs process hollowing. Storm 249 uses clickfix to download a legitimate executable vulnerable to DLL sideloading. Its malicious DLL runs inside a trusted signed process. Cookbook stores encoded code across multiple registry keys and uses PowerShell Invoke-Expression to execute it. Head Crab targets Redis servers exposed on the internet with default credentials, runs SLAVEOF to load shared objects, and deploys crypto miners.

Defense Requires Human Training and Technical Controls

โ–ถ Watch (27:19)

82% of attacks involve human interaction; 70% could be prevented by proper training. Windows ASR rules block WMI persistence and obfuscated code execution. PowerShell constrained language mode limits functionality abused by malware. Reduce the footprint of binaries like certutil and bitsadmin by blocking outbound connections to unknown IPs. Audit PowerShell commands even when obfuscated. Use the open-source LOLBAS project for detection rules. EDR behavioral analysis detects process hollowing and script execution.

Q&A

How would you write a YARA rule for Tactical RMM, which uses HTTPS on port 443 and can be self-hosted by an attacker? Monitor threat feeds for malicious IPs and domains where the attacker hosts the tool, and write detections based on those indicators. โ–ถ 37:39

Have any attacks been defeated by removing the abused features from LOTL binaries? Not that I know of. Vendors are reluctant to remove arguments because they are used by legitimate programs. Removing them could break functionality. โ–ถ 39:25

Once you find an intrusion, how do you clean the machine? Restore from a backup taken before the infection. If backups are unavailable, run antivirus and cleaning tools, but 100% removal is difficult due to WMI and registry hooks. โ–ถ 41:48

Notable Quotes

47% of initial access was by clickfix type of vulnerabilities or clickfix type of attacks Amol Sarwate ยท โ–ถ 5:17

84% of incidents had living off the land binaries associated with it Amol Sarwate ยท โ–ถ 3:41

Legitimate tools are the new threats Amol Sarwate ยท โ–ถ 36:39

Key Takeaways

  • Fileless LOTL attacks dominated 84% of incidents in 2025, using trusted binaries to evade detection.
  • Clickfix overtook phishing as the top initial vector, driving 47% of breaches.
  • Defense combines user training, Windows ASR rules, PowerShell lockdown, and behavioral EDR.

About the Speaker(s)

Amol Sarwate leads security research and RedLab at Cohesity, where he focuses on cutting-edge research into emerging threats and threat intelligence to build resilient defenses. With over 25 years of experience across data, endpoint, network, and cloud security, Amol has held leadership roles in security research and product development.